Summary
Mozilla’s Zero Day Investigative Network (0DIN) documented an indirect prompt-injection attack on June 30, 2026 that compromises developer machines running Claude Code without placing malicious code in the repository. The attack chain uses a fake open-source project (“Axiom”) with a deliberate RuntimeError, setup script fetching a base64-encoded reverse shell from a DNS TXT record, and Claude Code’s autonomous error recovery to execute the payload. The technique exposes API keys, cloud credentials, and GitHub tokens. Payloads can be swapped via DNS without new commits, evading diff-based security tooling.
Source Analysis
Research Notes
Draft Article
PreScreening Notes
Score: 3 | Route: rejected
Same Mozilla 0DIN Claude Code DNS TXT attack already tracked, analyzed, reported, and archived in pipeline/7-done/2026-06-27-mozilla-0din-claude-code-github-malware.md. Cyber Press article is secondary coverage of an existing story, not new developments.